Technology Security Manager

5 days ago


London Area, United Kingdom Chelsea Football Club Full time

JOB TITLE
Technology Security Manager

DEPARTMENT:
Technology

LOCATION:
Stamford Bridge (London) with occasional travel to Cobham (Surrey).

CONTRACT:
Permanent.

JOB FUNCTION:
This position is responsible for leading the strategic and operational direction of Chelsea FC's Information and Cyber Security, reporting into to the Director of Technology.

This role is both strategic and operational: it defines the security vision, embeds governance, and drives risk reduction across the Club's football and commercial operations, while also providing leadership in day-to-day cyber defence.

The postholder will influence senior leadership, ensure compliance with key regulations, and work with internal teams and external partners to build a resilient, future-ready security posture that enables innovation on and off the pitch.

Closing date: 13th November

We encourage you to apply as soon as possible. In the event that we receive a large number of applications, the position may be filled before the listed closing date. To avoid missing out, please submit your application at your earliest convenience.

MAIN RESPONSIBILITIES:

1. Strategic Leadership and Governance:

  • Define and evolve Chelsea FC's cybersecurity strategy aligned with Club objectives and industry best practice.
  • Lead the development and enforcement of information security policies, standards, and frameworks.
  • Drive the Information Security Risk Management programme, reporting on key risks, mitigation, and maturity progress.
  • Provide strategic security insights to the Information Security Steering Committee, Director of Technology, COO, CDO, CFO, CEO, etc. - as required.
  • Act as subject matter expert and advisor to executives and other business stakeholders on cyber risk, emerging threats, and technology opportunities.

2. Risk and Compliance

  • Ensure compliance with all applicable standards and regulations, including PCI DSS, GDPR, and Premier League cybersecurity requirements.
  • Oversee periodic independent security maturity assessments and ensure remediation plans are executed.
  • Maintain the risk register in collaboration with IT, Risk & Compliance, and business stakeholders.
  • Embed security considerations into procurement, contract negotiations, and third-party vendor management.

3. Security Operations

  • Provide senior oversight for security operations, ensuring effective monitoring, detection, and response.
  • Govern the SOC provider, ensuring SLAs and threat detection capabilities meet the Club's requirements.
  • Lead response to significant security incidents, engaging with senior leadership, regulators, law enforcement, and insurers.
  • Ensure a robust vulnerability management and penetration testing programme is in place and actioned.
  • Oversee endpoint, email, and identity security across the Club's workforce and infrastructure.

4. Secure Technology and Development

  • Champion secure design and "security by default" across infrastructure and applications.
  • Oversee identity and access management, including MFA, privileged access, and zero trust principles.
  • Lead the adoption of SSDLC/DevSecOps practices across the Club's development workflows.
  • Partner with Infrastructure and Cloud teams to ensure Azure, GCP, Microsoft 365 and AWS environments are governed and secure.

5. Culture, Awareness and Training

  • Develop and deliver the Club's security awareness programme, including phishing simulations, campaigns, and training.
  • Provide security briefings and horizon-scanning reports for senior leaders.
  • Ensure new employees receive induction training in information security.
  • Promote a culture of shared responsibility for security across all functions.

6. Programme and Change Leadership

  • Act as security lead on major transformation projects (e.g., CCTV infrastructure upgrade, authentication improvements, data warehouse programmes).
  • Embed security into the Technology change management process, ensuring early engagement and risk identification.
  • Evaluate and approve new third-party tools and SaaS platforms from a security perspective.

KEY RELATIONSHIPS:

Internal:
Director of Technology, Risk & Compliance, Legal, HR, Technology Infrastructure, Service Desk, Facilities, Football Operations, Marketing & Commercial teams, Physical Security, Matchday Safety, etc.

External:
SOC, Microsoft, Security Vendors, cyber insurers, regulators, and law enforcement (NCSC, Action Fraud), Payment Service Providers, Credit Card Schemes, Cyber Insurer, Premier League

MEASURES OF PERFORMANCE:

  • Effective management of IT security risks and incidents.
  • Compliance with organisational and regulatory standards.
  • Reporting on security.
  • Operational efficiency and cost management in line with budgetary goals.
  • Successful alignment of security strategy with organisational outcomes.

EXPERIENCE/REQUIREMENTS:

Essential:

  • Significant experience in an information security leadership role (e.g. Security Manager) within a complex, high-profile organisation.
  • Strong knowledge of: Cloud security (Azure, GCP, Microsoft 365).
  • Security operations (EDR, SIEM, SOC workflows).
  • Governance and regulatory frameworks (PCI DSS, GDPR, ISO 27001 desirable).
  • Demonstrable experience of leading incident response, risk management, and vulnerability management programmes.
  • Track record of influencing senior stakeholders and presenting at executive/Board level.
  • Proven ability to manage third-party vendors and contracts.

Desirable:

  • Information security management qualifications (e.g., CISSP, CISM).
  • Knowledge of Enterprise Architecture methodologies (e.g., TOGAF).
  • Familiarity with ITIL Service Management practices.

Our commitment to Equality, Diversity and Inclusion:

At Chelsea we recognise that the diversity of our people is one of our greatest strengths and we are taking positive action to ensure our existing colleagues and job applicants can fully be themselves and bring their own unique experiences and perspectives to Chelsea FC. This means giving full and fair consideration to all applicants regardless of age, disability, gender reassignment, race, religion or belief, sex, sexual orientation, marriage and civil partnership, and pregnancy and maternity.

If you need reasonable adjustments made to the recruitment process, please reach out to your recruiter, who will be able to advise and support you.

Chelsea FC is fully committed to ensuring the safety and well-being of all children, young people and adults at risk (vulnerable groups). We therefore require all successful applicants to complete a DBS Check prior to starting employment. Depending on the role, successful applicants may also be required to undergo other child protection screening where appropriate.



  • London Area, United Kingdom Revolution Technology Full time

    Group IT & Security Manager | Up to £75k | London, hybridIn this role, you'll be in charge of both strategic direction and hands-on technical support across groups You will be integral when it comes to resilience, compliance, and innovation within the infrastructure and IT systems.Additionally, with the increasing popularity of AI, you will be at the...


  • London Area, United Kingdom Acre Security Full time

    Position:Security Systems EngineerLocation:London, UKMove Security Forward with AcreAre you passionate about transforming the future of security? Do you thrive in a collaborative, innovative environment where your contributions drive real impact? If so, Acre Security is the place for you. Join us in making the world a safer place — one innovation at a...


  • London Area, United Kingdom Insite Risk Management Full time

    About the jobPosition Description: Security Technology Intermediate EngineerThe Security Technology Intermediate Engineer will utilize specialized knowledge to support the deployment, integration, maintenance, and upgrading of physical security systems. In collaboration with the Managing Director of Security Technology and Security Consulting team, the...

  • Duty Security Manager

    18 hours ago


    London Area, United Kingdom Ward Security Full time

    Do you have previous security experience and excellent communication skills? Do you provide exceptional customer service and maintain a professional demeanour at all times? Can you keep a positive mindset with any challenge that comes your way?…Apply nowWard Security is on the lookout for an experienced Duty Shift Manager, to join a team of operatives...


  • London Area, United Kingdom LT Harper - Cyber Security Recruitment Full time £120,000 - £180,000 per year

    Operational Technology (OT) Cyber Security Lead — Practice BuilderSalary:£150k–£165k + bonus/benefitsLocation:UK / Ned |Hybrid:Site (~35%) • Office • HomeRelocation to the Netherlands is an option - must be fluent in EnglishThis role is for a leader who wants to deliver andgrow a high-performing OT security practice, shape go-to-market, mentor, and...


  • London Area, United Kingdom Revolution Technology Full time

    Group IT & Security Manager | up to £74,000 | Hybrid/LondonGroup-level role leading IT and Security across multiple fast-growing businesses, from regulated, data-sensitive environments to agile, tech-driven startups.As Group IT & Security Manager, you'll shape and lead the infrastructure, IT, and security function while staying hands-on across Microsoft,...


  • London Area, United Kingdom Revolution Technology Full time

    IT Manager RoleThis is a Group IT & Security Manager role. You'd be stepping in to oversee IT across 3 start-ups in the prop-tech spaceKey Responsibilities:Microsoft and Mac EnvironmentsCloud and Infrastructure- with a focus on AWSMaintaining Cybersecurity Essentials standardsIntroducing AI/ Automation toolingWhat they need from you:Experience with...


  • London Area, United Kingdom LT Harper - Cyber Security Recruitment Full time £150,000 - £165,000 per year

    Operational Technology (OT) Cyber Security LeadSalary:£150k–£165k + bonus/benefitsLocation:UK / Netherlands | Hybrid -Relocation to NL an option • English fluency requiredIf you're driven bybuilding something big—growing revenue, shaping a market presence, and leading delivery excellence, this role gives you the platform to do it.This is a top-tier...


  • London Area, United Kingdom Assist Security Group Full time

    We're Hiring: Pre-Sales Technical Manager – Security SystemsLocation: United Kingdom (Hybrid / Field-Based, Head Office: London)Reports to: Chief Business Development OfficerEmployment Type: Full-Time, PermanentAbout Assist Security Group:With over 30 years' experience, Assist Security Group is a trusted provider of security solutions, known for quality,...


  • London Area, United Kingdom Morson Edge (Technology) Full time

    We are seeking an accomplishedInterim Chief Information Security Officer (CISO)to lead a critical period of transformation and uplift across our security and technology risk landscape. This strategically significant leadership role is ideal for an executive who has successfully delivered complex security transformation programmes, enhanced organisational...